fix(caddy): socket-activate 80/443 so real client IPs reach caddy (#81) #94
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!94
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/81-caddy-socket-activation"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Fixes #81 — rootless Podman's pasta port forwarding rewrote every inbound source to the container network, so Caddy logged its own
10.89.0.15for all external requests and forwarded it inX-Forwarded-For.Approach: systemd socket activation (issue's candidate 1)
The systemd user manager binds 80/443 on the host (
caddy.socket) and passes them into the container as inherited fds — pasta never touches inbound connections, so source addresses survive. Bonus: the sockets stay open across Caddy service restarts, so config deploys no longer drop connections; and Caddy now needs zero capabilities (NET_BIND_SERVICE dropped along with PublishPort).caddy.socket(new template): 443/tcp, 443/udp (HTTP/3), 80/tcp; dual-stack viaBindIPv6Only=both; fd order documented in the unit and mirrored by the Caddyfile(socket_bind)snippet — fd/3 h1+h2, fdgram/4 h3, fd/5 http.caddy.container:Requires=caddy.socket+After=so fds are passed even on a direct service start (boot, deploys).Caddyfile: each site imports(socket_bind);auto_https disable_redirects+ explicithttp://server on fd/5 doingredir https://{host}{uri} permanent. ACME HTTP-01 is still solved (Caddy intercepts challenges on every server); TLS-ALPN-01 on fd/3 is the fallback.Verified in the local podman machine (podman 5.8.3, systemd 259, caddy 2.11.4-alpine — prod tag)
127.0.0.1from loopback curl); a published-port control container logs the bridge address (10.88.0.7) — the exact #81 symptom.systemctl --user restartof the service (important: the #63 fix restarts Caddy on unit changes).{host}strips the port).caddy validateon the prod image.Apply-day notes
systemctl --user status caddy.socketactive; fresh external request shows a publicremote_ipin~gitborg/caddy/logs/access.log; Forgejo logs the real IP end-to-end.curl --http3if available); if it misbehaves, dropping thefdgram/4bind +ListenDatagramline falls back to h1/h2 only. Tracked in #101.Unblocks / follow-ups
b1df99576666d811a2b0